CVE-2026-45270
- EPSS 0.21%
- Veröffentlicht 20.07.2026 14:12:13
- Zuletzt bearbeitet 21.07.2026 20:27:18
CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify` validation rule on language-keyed page content but persists the raw, un-purified POST value into the ...
CVE-2026-45139
- EPSS 0.27%
- Veröffentlicht 20.07.2026 13:58:39
- Zuletzt bearbeitet 21.07.2026 20:27:18
CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enforces an extension allowlist (`['css','js','html','txt','json','sql','md']`) on content-write operations (`saveFile`, `createFile`)...
CVE-2026-45138
- EPSS 0.15%
- Veröffentlicht 19.07.2026 23:18:51
- Zuletzt bearbeitet 21.07.2026 20:27:18
CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the custom `html_purify` validation rule used to sanitize blog post bodies relies on by-reference mutation (`?string &$str`), but CodeIgniter 4's validator ...
CVE-2026-41891
- EPSS 0.27%
- Veröffentlicht 07.05.2026 04:16:33
- Zuletzt bearbeitet 07.05.2026 14:57:13
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. From version 0.26.0 to before version 0.31.8.0, the auth filter has the deactivated/banned user check commen...
CVE-2026-41890
- EPSS 0.34%
- Veröffentlicht 07.05.2026 04:16:33
- Zuletzt bearbeitet 07.05.2026 15:16:09
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. From version 0.31.1.0 to before version 0.31.8.0, the deleteProcess() action accepts a POST parameter tables...
CVE-2026-41587
- EPSS 0.5%
- Veröffentlicht 07.05.2026 04:16:27
- Zuletzt bearbeitet 07.05.2026 15:16:07
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. From version 0.26.0.0 to before version 0.31.7.0, a theme upload feature allows any authenticated backend us...
CVE-2026-41203
- EPSS 0.48%
- Veröffentlicht 07.05.2026 04:16:27
- Zuletzt bearbeitet 07.05.2026 15:16:06
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.5.0, ci4ms Theme::upload extracts user uploaded ZIP archives without validating entry ...
CVE-2026-41202
- EPSS 0.53%
- Veröffentlicht 07.05.2026 04:16:27
- Zuletzt bearbeitet 07.05.2026 14:57:13
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.5.0, ci4ms Backup::restore extracts user uploaded ZIP archives without validating entr...
CVE-2026-41201
- EPSS 0.33%
- Veröffentlicht 07.05.2026 04:16:26
- Zuletzt bearbeitet 07.05.2026 14:57:13
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. In version 0.31.4.0, an attacker can achieve Full Account Takeover & Privilege Escalation via Stored DOM XSS...
CVE-2026-39394
- EPSS 0.52%
- Veröffentlicht 08.04.2026 14:32:31
- Zuletzt bearbeitet 24.07.2026 21:10:00
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the Install::index() controller reads the host POST parameter without any validation and ...